THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-c8qc-wf67-342w (medium) — Snipe-IT: Stored DOM XSS via table selected-count IDs

[GHSA] GHSA-c8qc-wf67-342w (medium) — Snipe-IT: Stored DOM XSS via table selected-count IDs

highgithub_advisoriesPublished 2026-08-19

GHSA-c8qc-wf67-342w Severity: medium CVE: CVE-2026-61807

Snipe-IT: Stored DOM XSS via table selected-count IDs

### Impact The table component derives data-selected-count-id from the component $name value. On manufacturer and supplier detail pages, stored manufacturer or supplier names are passed into affected table components as that name value. The client-side JavaScript later reads the browser

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-c8qc-wf67-342w